All verified exploits

CVE-2026-24423 Unauthenticated RCE via ConnectToHub

Deterministic critical SmarterMail Added cve-verified-cve-2026-24423

Identifies vulnerable SmarterMail builds and confirms the admin ConnectToHub endpoint accepts unauthenticated requests, proving remote code execution is possible.

Is your app exploitable through CVE-2026-24423?

Scan your domain free